RHSA-2019:3172MediumCVSS 9.0

Red Hat Security Advisory: Red Hat Satellite 6 security, bug fix, and enhancement update

Published
October 22, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2016-10516 — python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.py CVE-2016-10745 — python-jinja2: Sandbox escape due to information disclosure via str.format CVE-2018-16470 — rubygem-rack: Buffer size in multipart parser allows for denial of service CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents CVE-2019-3893 — foreman: Recover of plaintext password or token for the compute resources CVE-2019-10198 — foreman: authorization bypasses in foreman-tasks leading to information disclosure CVE-2019-10906 — python-jinja2: str.format_map allows sandbox escape CVE-2019-12387 — python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods CVE-2019-14825 — katello: registry credentials are captured in plain text during repository discovery

🎯 Affected products200

  • Red Hat Satellite 6.6
  • Red Hat Satellite Capsule 6.6
  • ansible-runner-0:1.3.4-2.el7ar.noarch as a component of Red Hat Satellite 6.6
  • ansible-runner-0:1.3.4-2.el7ar.noarch as a component of Red Hat Satellite Capsule 6.6
  • ansible-runner-0:1.3.4-2.el7ar.src as a component of Red Hat Satellite 6.6
  • ansible-runner-0:1.3.4-2.el7ar.src as a component of Red Hat Satellite Capsule 6.6
  • ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.noarch as a component of Red Hat Satellite 6.6
  • ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
  • ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.src as a component of Red Hat Satellite 6.6
  • ansiblerole-foreman_scap_client-0:0.0.3-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
  • ansiblerole-insights-client-0:1.6-2.el7sat.noarch as a component of Red Hat Satellite 6.6
  • ansiblerole-insights-client-0:1.6-2.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
  • ansiblerole-insights-client-0:1.6-2.el7sat.src as a component of Red Hat Satellite 6.6
  • ansiblerole-insights-client-0:1.6-2.el7sat.src as a component of Red Hat Satellite Capsule 6.6
  • candlepin-0:2.6.9-1.el7sat.noarch as a component of Red Hat Satellite 6.6
  • candlepin-0:2.6.9-1.el7sat.src as a component of Red Hat Satellite 6.6
  • candlepin-selinux-0:2.6.9-1.el7sat.noarch as a component of Red Hat Satellite 6.6
  • createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite 6.6
  • createrepo_c-0:0.7.4-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
  • createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
  • createrepo_c-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
  • createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
  • createrepo_c-debuginfo-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
  • createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite 6.6
  • createrepo_c-libs-0:0.7.4-1.el7sat.x86_64 as a component of Red Hat Satellite Capsule 6.6
  • foreman-0:1.22.0.32-1.el7sat.noarch as a component of Red Hat Satellite 6.6
  • foreman-0:1.22.0.32-1.el7sat.src as a component of Red Hat Satellite 6.6
  • foreman-0:1.22.0.32-1.el7sat.src as a component of Red Hat Satellite Capsule 6.6
  • foreman-bootloaders-redhat-0:201901011200-1.el7sat.noarch as a component of Red Hat Satellite 6.6
  • foreman-bootloaders-redhat-0:201901011200-1.el7sat.noarch as a component of Red Hat Satellite Capsule 6.6
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.6/html/upgrading_and_updating_red_hat_satellite/updating_satellite_server_capsule_server_and_content_hosts Workaround: If you don't want or you cannot upgrade Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow all `format` attributes on strings. Workaround: Do not grant the "destroy_compute_resource" permission to users that should not know the password. Workaround: If you cannot upgrade python-Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow the `format_map` method on string objects.

🔗 References (119)